Saturday, 31 December 2016

What will 2017 bring in Cyber Security?

5 Cyber Security Predictions for 2017

Lots of people do these type of lists, but since this is the end of my first year in business, I might as well be no different.😏

1. Ransomware levels will plateau, but constantly change

This might be an easy one to get right. Ransomware is already embedded in over 90%+ of all phishing e-mails, so there's hardly any further room to keep growing. We've already started to see the way it is changing though. As was reported earlier this month, you could get your files unlocked if you infected two friends with this Ransomware rather than paying money over to the hackers.

2. Smart Device Botnets will target the big service providers

We've seen record breaking botnets created this year by poorly designed and poorly secured smart devices (also referred to as IoT, e.g.- internet connected cameras, digital video records, internet routers, etc.). I suspect the evil doers are building a massive army, much bigger than anything we have seen to date. I believe that they will then carry out a coordinated attack on one of the big service providers (e.g.- Google, Amazon or Microsoft). The attack won't be fully successful, but will have caused sufficient disruption to make smart device security a focus for all manufacturers of such devices, as insecure devices will be banned from accessing the web.

3. There will be an even bigger data leak than 2016's revelation of the Yahoo! world record leak

Yahoo! has really had a bad year, setting a world record, having already had an even bigger world record. I believe bigger leaks have already happened and will be revealed next year. I reckon the bad guys are already combing through the data, cracking passwords and will then create tools that will take the IDs and passwords they have and try these against other services (e-mail, social media, etc.) to generate a list of compromised accounts, which are extremely valuable on the dark net.

4. Russia will be accused of interfering in elections occurring across Europe

Russia has shown form this year, interfering with the US Presidential Election. With elections happening in the bigger European Countries (Germany, France and The Netherlands) in 2017, I would not be very surprised to discover that the Russian state hackers tried to influence the results of these.

5. More Irish people will be protecting themselves from Cyber Threats


I'll be a bit selfish with this one as I will be the one helping these people to protect themselves. People knowing how to stay safe on-line will be the least likely to be affected by a Cyber Threat.

Happy New Year to you all!

So I'll come back in 364 days and see how I did. Then the following day, I'll make another list. 😃

Wishing all my clients and contacts and safe and secure 2017.

Let's be care out there.

Thursday, 29 December 2016

Facebook Messenger scam ... it's nothing new, but it's still effective.

I've seen evidence of this scam occurring amongst my Facebook friends this Christmas. It's a straightforward phishing scam, where one of your friends sends you a Facebook Message with an apparent link to a video of you. Sometimes they might ask "Is this you?" or tell you to go a specific point in the video to see yourself. Of course what has happened is your friend's account has been hacked and the scammers are using your friend's contact list to spread their evil wares.

This is an example of a message that a friend of mine received from one of their Facebook friends. I've blurred the pics and redacted the name to protect the parties involved:
This is pretty compelling. It looks like there is a video of you on YouTube with nearly 384K views. You've got to go see what everybody is looking at ... right? 

WRONG!

If you click on this, it will either take you to a web page that asks you to sign-in to Facebook with your ID and password or it tries to install a facebook app and looks for various permissions to your Facebook profile.

If you proceed with either signing in or installing the app, then your Facebook profile now belongs to the bad guys. They will mercilessly spam and phish your Facebook friends. 

If you have fallen for this, then first thing to do is remove the app from your Facebook account (if it has access). Go to Facebook -> Settings -> Apps and locate the offending app and remove it's access. You could also go into Facebook -> Settings -> Blocking and block the app there too.

Next thing you must do is change your Facebook password. You will find this under Facebook -> Settings -> General.

And finally, if you had used the same password for Facebook and for your e-mail, for the love of dogs, change your e-mail password right now and change it to something else completely different to your Facebook password. If the evil doers compromise your e-mail account, your online life will become a lot more troublesome for you than a few spammy Facebook messages.

Finally, finally - if you have not already done so, turn on Two Step Verification/Login Approvals/Two Factor Authentication, whatever they call it, on your all of the on-line accounts that you have, which have this feature. What this means is that not only do you have to have your user ID and password to access your account, but also a code generated by an App on your phone or a text message sent to your phone which adds another layer of protection. If the bad guys get your ID and password, they won't be able to compromise your account without access to your phone.

There's more detail about this subject here:

Let's be careful out there.

Thursday, 22 December 2016

Could the attempted theft of €4.3m from Meath County Council happen to your business?

As was widely reported at the weekend, Meath County Council were the victim of an attempted theft of some €4.3 million. A lot of the reportage was pointing to hackers and this being a cyber attack, but based on what is known, in my opinion, it's not really.

This attempted theft was facilitated by the use of technology, but not necessarily the abuse of it. They're no longer commenting about it now while the matter is investigated, so we'll need to await the outcome of that before we know for sure.

However this sort of theft is incredibly common and is known variously as CEO fraud or Business Email Compromise (BEC). Basically what the bad guys do, is send an e-mail or even a text message that appears to come from the CEO, the MD, the Head Honcho, the Big Boss. This e-mail/text is sent to somebody in the finance department and it instructs them to urgently transfer or wire funds to some account that is outside of the EU area. If the transfer was within the EU area, it can be recalled under SEPA regulations, but outside of the area the money can be a taken and never seen again. 

Wednesday, 21 December 2016

Don't ignore that e-mail from Lynda.com

I received two e-mails in recent days from online training provider Lynda.com customer care, this is because I have had two accounts with Lynda.com in the past. Both were set-up when they had a 30 day free trial offer, which I made use of.

I'm one of the 9.5 million customers/former customers of Lynda.com who have been contacted by them about a breach of their data security. They state that my contact information and courses taken were compromised, however they believe my password was not compromised. Here is the text of the e-mail:
We recently became aware that an unauthorized third party breached a database that included some of your Lynda​.com learning data, such as contact information and courses viewed. We are informing you of this issue out of an abundance of caution.
Please know that we have no evidence that this data included your password. And while we have no evidence that your specific account was accessed or that any data has been made publicly available, ​we wanted to notify you as a precautionary measure.
So this doesn't sound so bad. Right?

Tuesday, 20 December 2016

Yahoo! tries for new world record and wins ... but it already had the world record!

You all heard the headlines during the year about the massive Yahoo! hack, where in late 2014, hackers had stolen the names, addresses, mobile telephone numbers, dates of birth, security questions and passwords of 500+ million accounts. This was a new world record for the amount of user accounts stolen on the internet.

Well bless their cotton socks, Yahoo! had actually already done even better and they didn't even realise it. In 2013 over 1 billion accounts had the same type of information stolen, including poorly protected passwords. Yahoo! had no idea that this had happened. It wasn't until somebody provided the authorities with details that they had come across on the web. The authorities brought this to Yahoo! in October/November, which was when they were still thrashing around after the the September revelations about the 500m accounts, and I can just imagine their response...


Monday, 19 December 2016

Do you own a Netgear router? If so, you may have a serious vulnerability.

Netgear Routers Vulnerable


If you have one of the following Netgear router models, you could be exposed to a serious vulnerability:
  • R6250
  • R6400
  • R6700
  • R7000
  • R7100LG
  • R7300
  • R7900
  • R8000
There is a simple test that you can carry out to determine if you have a vulnerable router. From a device connected to the router, open the following link in a browser:
     http://www.routerlogin.net/cgi-bin/;echo$IFS'Vulnerable!'
If you see a simple webpage that says Vulnerable!, then you have an affected router.

The risk with this vulnerability is that hackers can scan the internet looking for these routers and if they detect one, they can take it over quite simply and use it for nefarious purposes.

Netgear have made some patches available, but not for every model at the moment. These patches require technical skills to install safely, so please contact your IT support provider. Don't expect your teenager to be able to do this, unless they have already had experience of flashing router firmware successfully before. Making a mistake when doing this, could render the router unusable.

While you await for the router to be patched, you can protect yourself by opening the following link in a browser:
Once you have done that try the previous link above to see if it still says Vulnerable! 

If you reboot/restart the router after this, you will need to open that last link above again.

If you have any questions or concerns, please contact us on info@L2CyberSecurity.com or call us on 087-436-2675.

Thursday, 27 October 2016

There is a lot of variations in evil e-mail the last couple of days.

I yearn for the days when evil e-mail was so easily identified "becuse it wuz ritten in, gud, inglish wit grate spellhng an pun.tation". 😃

In the last couple of days, the evil doers have been varying their scam e-mails fairly wildly and it's bound to catch out some people.

I'll run through three sneaky methods that have been attempted on others over the last 48 hours.

Wednesday, 26 October 2016

If you have Adobe Flash Player installed, read this now.


I really HATE Adobe Flash player. 😡 It is the internet equivalent of Typhoid Mary. If you don't need it, uninstall it. If you do need it, use Chrome as your browser. Why the rant?

Adobe has released a Critical update to Flash Player because of a vulnerability with it that has already been exploited in targeted attacks against Windows.
https://helpx.adobe.com/…/produ…/flash-player/apsb16-36.html


If you use Chrome or Microsoft's Edge or Internet Explorer 11, then the Flash player built in to these will get updated automatically. So concern yourself not.

However if you use Internet Explorer 10 or less (check Help->About) or other browsers and have Flash Player installed, then go to the following link and be sure to UNCHECK the "Optional Offers" and Click "Install Now" and follow the directions to upgrade your Flash Player.
https://get.adobe.com/flashplayer/

The sooner Flash goes away, the happier I will be. 😉

In the meantime ... Let's be careful out there.

The Internet of Evil Things continues to grow.

The first time I saw that cover picture Dr. Evil meme, I never thought that it might be possible for the numbers to reach those nonsensical values, but if Internet connected brooms are in our future (see below), we might be in serious trouble, if the manufacturers of such devices keep ignoring the need for easily configured security settings on their gear.

The Mirai Botnet, which was responsible for the historic attack on Brian Krebs website, amongst others last month has grown dramatically. I came across this Botnet tracking website, which gives details of the number of infected hosts in the Mirai Botnet a few hours ago. At that time the total number of hosts was 1,479,110. It is now showing 1,547,552 (it'll be higher by the time you read this 😭) That means on a Wednesday morning in late October, another 68,000 devices have been hacked and are ready to be used for evil purposes. It is believed that last Friday's massive attack on Dyn, which crippled such services as Twitter, Amazon, Spotify, PayPal and Netflix, was partly as a result of the Mirai Botnet according to Flashpoint.

Monday, 24 October 2016

Details emerge about the huge internet attack last Friday.


I'm sure you've all heard about the internet attack in the US last Friday, where sites such as Twitter, Amazon, Spotify, PayPal and Netflix (amongst others) were taken offline (effectively).

This was done by what is called a Distributed Denial Of Service (DDOS) attack and it targeted a company called Dyn, which provides all of those companies with a specific service. It is believed that this attack was carried out by a huge number of hacked security cameras and their associated Digital Video Recorders (DVRs), flooding the service with billions of requests which it could not handle. I talked about these hacked devices last month in this blog post.

Since then the hacker that created the computer code to take control of the cameras, has released it to the internet, so it looks like some new bad guys may have stepped it up a bit as there was mention of between 500,000 and 1,000,000 devices being used last Friday.

This is a very worrying situation, as that many devices could cause serious disruptions to businesses and people worldwide. There are anecdotal reports that some of these evil doers are attempting to bribe online service providers to pay them money not to launch an attack.

There is an excellent briefing by Dr. Johannes Ullrich of the SANS Institute in the following YouTube clip. This is a little tech jargon heavy, so only watch if you are really interested in learning more about this attack.

Thursday, 29 September 2016

Have you a smart internet connected (IoT) device in your home?



If so, you may be an unwilling accomplice to the evil doers who are attempting to disrupt the internet.

Do you have any one or more of the following Internet of Things (IoT) devices which you can access from outside the home, over the internet:
  • Security Cameras or Digital Video Recorders (DVRs)
  • Baby monitor
  • Smart sockets
  • Smart light bulbs
  • Smart Thermostat
  • Energy usage monitor
  • Smart fridge
  • Media Server


Using the Internet Safely. Training from L2 Cyber Security Solutions.

Human Error
Did you know that evil software gets past commercial anti-virus and e-mail filtering products on a worryingly regular basis.

Firewalls and Anti-virus packages lure people into a false sense of security. While they do provide protection up to a point, if somebody opens an e-mail attachment that contains new Malware, these protections are effectively useless.

Cyber incidents, most notably Ransomware attacks have seen massive increases recently. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

These statistics highlight the fact that a significant weak link in any organisation, where it comes to using the internet and e-mail, are THE STAFF, but it's not their fault.

The best protection to cover this gap are staff that are aware of what the threats are and how they manifest themselves. Once they are armed with the knowledge of what to look out for, they will be much less likely to cause a security breach.

The training that L2 Cyber Security Solutions delivers is comprehensive, yet simple for all to follow.

Using the Internet Safely

Course Outline

Lecture / Workshop


Duration:

1 day


Audience:

People who have access to and utilise the internet and e-mail, whether for personal or business purposes, as part of their day. 


Prerequisites:

A basic understanding of internet browsing and e-mail usage is a prerequisite.


Programme Aim:

This training will give the attendees an understanding of the risks and threats associated with using the internet and e-mail.


Learning Outcome:

The participants will know how they can take some simple steps to avoid being adversely affected by the various risks presented to them. They will also learn how to create unique and strong passwords.


Course Content:

  1. Malware (incl. Ransomware)
  2. Spam
  3. Social Engineering
  4. Phishing and Spear-Phishing (incl. CEO Fraud)
  5. Safe Web Browsing
  6. Good Security Practices
  7. Mobile Security
  8. Creating a unique and strong password

Call us on 087-436-2675 or e-mail info@L2CyberSecurity.com to discuss your requirements and get a quotation.

Friday, 23 September 2016

Here is a worrying aspect of the Yahoo breach.

Everyone has heard about the personal information related to 500 million Yahoo accounts being stolen from Yahoo in 2014. There's lots of helpful tips out there (and some here too), but some people may not realise that they have a Yahoo account.

Yahoo provides e-mail services to some big internet service providers (ISPs), over in the US AT&T, Rogers and Frontier.com. Over on this side of the Atlantic Sky and BT are large ISPs operating in Ireland and the UK. Their e-mail services are powered by Yahoo.

Snail mail delivers USB keys ... WTF?


I find I'm writing a second article about Evil USBs within a week. At least these ones don't destroy your equipment, but they might infect you with nasty software that does things that you really wouldn't want it doing.

In this case, in Victoria, Australia, Evil Doers were dropping USB drives into people's mailboxes. The report from Victoria Police stated:
Upon inserting the USB drives into their computers victims have experienced fraudulent media streaming service offers, as well as other serious issues.
The USB drives are believed to be extremely harmful and members of the public are urged to avoid plugging them into their computers or other devices.

Friday, 16 September 2016

A desktop/laptop killing device is on sale for €50.

As I'd mentioned in the detail section of a previous blog post there was a prototype USB memory stick that is designed to fry the electronics on a laptop or desktop, the instant it gets plugged into it.

Well it's now something you can buy for as little as €50. The worrying thing is, as of today (16th September 2016) they are out of stock!

What purpose does this device serve? 

According to their website "The USB Kill 2.0 is a testing device created to test USB ports against power surge attacks. The USB Kill 2.0 tests your device's resistance against this attack." Unfortunately in testing your device, this stick literally kills it!

Monday, 12 September 2016

Protect your on-line accounts, but not with text messages.

As I outlined here, if you are using an on-line account for e-mail, social media, etc. then one of the strongest means of protecting yourself from the evil doers is to use, what is called, two factor authentication. If you are not doing this now, you really should be as it improves your protection massively.

This is where you can set your on-line account to not only request your user ID and password (something you know) but also using your phone (something you have) by way of an app or sending you a text message with a code that you enter on the site to confirm you are you

If you have this set-up to authenticate by a SMS Text message, then a bad guy who has access to your LinkedIn details from the 2012 hack should not be able to access your e-mail account using the password that they have recovered from there, because as soon as they try to access your e-mail account, you will be sent a text message. So you're safe ... right?

Wednesday, 31 August 2016

Repeat after me ... Microsoft do NOT e-mail out system updates!


More evil e-mail is coming to scramble all the files on your computer and then demand you to pay your hard earned cash in order to get back access to same. In other words you are being held to Ransom and so we get the term Ransom Software or Ransomware for short.

Tuesday, 23 August 2016

Don't open that Voicemail!

The evil doers are up to their old tricks, trying to hoodwink people into opening up their dastardly files and execute their nasty contents. 

Usually they send files that claim to be invoices or bank statements, which will normally catch out a small percentage of their targeted group - accountants in this case, because accountants love opening invoices and bank statements, or so I've heard. 😉

So this new wheeze might catch out a hell of a lot more people, because everyone's got a phone. Right? And the vast majority of phones have a voicemail facility. Right? 

Tuesday, 16 August 2016

A Nightmare on Quadrooter Street.

When I was a teenager, watching slasher flicks like A Nightmare on Elm Street (the original 1984 version) and Halloween, in order to look like a "tough guy" I developed a sort of movie watching buffer whereby when any startling occurrence happened (e.g. the scary guy leaps out of the shadows), I would simply sit there all cool-like while all around me leaped out of their seats. I would mentally take a moment to let the occurrence happen and then internally say "Yep! That thing that happens in every scary movie happened" and just continue watching. I just don't react to the situation the instant it happens.

Nowadays I continue this type of trick when I read scary stories. For example, last weeks blog post about the Garda Síochána hack. After all the initial "Mob hack the Garda" hyperbole, it would appear, after a few days, that it was a simple Ransomware incident.

And so it is with the recent story from Check Point Software Technologies Ltd about their sexily named Quadrooter. A set of four vulnerabilities what they discovered in the Qualcomm chips that are in use in up to 900 million Android devices worldwide.

Tuesday, 9 August 2016

"Attack" on Garda systems is likely a Ransomware incident.

Now that the dust is settling after the IT Security incident, which caused the Garda Síochána (the Irish Police force) to shut down access to their systems late last week, it would appear that it wasn't quite as nefarious an incident as was being portrayed in the media.

Headlines such as "Mob target Garda computers" were wildly speculative and likely wildly wrong. 

According to Brian Honan, a respected IT Security expert, quoted in an article in today's Irish Times, "his 'best guess' was that the Garda systems had been hit by ransomware. From reading what’s available, this does not seem to me to be a targeted attack."

With reporters throwing around phrases like "Advanced Persistent Threat" (APT) and "Targeted Attack" like snuff at a wake, it's no wonder the headlines were sensational.

While full details are still not available, if this had been the result of a genuine Advanced Persistent Threat, then its quite likely that the evil doers were inside Garda systems for quite some time (that's what the "persistent" bit of this term means). In this case I wouldn't think they would have been able to restore access to their systems quite as quickly as they did. Hence a simple ransomware incident is quite likely.

Edit: Those fun guys over at Waterford Whispers News (a satirical website) had a different view:
http://waterfordwhispersnews.com/2016/08/09/we-tried-installing-windows-10-gardai-reveal-reason-behind-it-shutdown/

Thursday, 14 July 2016

Evil doers just being evil ... news at 11!

The good folk over at Cisco's Talos Threat Intelligence Organisation have been looking at a new piece of "apparent" Ransomware called Ranscam.

The reason I use "apparent" is because it doesn't hold any of your data to ransom, quite simply because it's deleted it already! That doesn't stop it trying to get you to pay them good money, and even if you did pay up, you'll get nothing in return.

As we covered in Commandment IV of our Ten Commandments, if you have a good backup set up, then you need not concern yourself with whether Ransomware has or has not locked away your data. You simply wipe your equipment of the nasty malware and restore your data.

Ranscam isn't too widely spread at the moment and Talos reckon it was cobbled together rather quickly to try to cash in on this Ransomware market.

You can read the Talos report here:

If you want to get your staff to learn what steps they can take to reduce the risk of your business being affected by Ransomware, then check out the Security Awareness Training that is available from L2 Cyber Security.

Monday, 11 July 2016

Security Awareness Training by L2 Cyber Security Solutions.

Cyber incidents, most notably Ransomware attacks have seen massive increases recently. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

These statistics highlight the fact that a significant weak link in any organisation, where it comes to using the internet and e-mail, are THE STAFF, but it's not their fault.

Firewalls and Anti-virus packages lure people into a false sense of security. While they do provide protection up to a point, if somebody opens an e-mail attachment that contains new Malware, these protections are effectively useless.

The best protection to cover this gap are staff that are aware of what the threats are and how they manifest themselves. Once they are armed with the knowledge of what to look out for, they will be much less likely to cause a security breach.


The training that L2 Cyber Security Solutions delivers is comprehensive, yet simple for all to follow.

Security Awareness Training

Course Outline

Lecture / Workshop


Duration:

1 day


Audience:

People who have access to and utilise the internet and e-mail, whether for personal or business purposes, as part of their day. 


Prerequisites:

A basic understanding of internet browsing and e-mail usage is a prerequisite.


Programme Aim:

This training will give the attendees an understanding of the risks and threats associated with using the internet and e-mail.


Learning Outcome:

The participants will know how they can take some simple steps to avoid being adversely affected by the various risks presented to them. They will also learn how to create unique and strong passwords.


Course Content:

  1. Malware (incl. Ransomware)
  2. Spam
  3. Social Engineering
  4. Phishing and Spear-Phishing (incl. CEO Fraud)
  5. Safe Web Browsing
  6. Good Security Practices
  7. Mobile Security
  8. Creating a unique and strong password


Call us on 087-436-2675 or e-mail info@L2CyberSecurity.com to discuss your requirements and get a quotation.

Thursday, 7 July 2016

The Ten Commandments of Cyber Security


Click on the links for a summary and detail of each commandment.
  1. Thou shalt keep all of thy software and apps up-to-date with automatic updates.
  2. Thou shalt have Anti-virus software installed, updated and active.
  3. Thou shalt have a firewall in place on thine Desktop/Laptop as well as thine internet connection.
  4. Thou shalt always back up thy data and regularly check its integrity.
  5. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you. (Corollary: Thou shalt never open an unexpected file/link from thine family, friends or colleagues)
  6. Thou shalt encrypt all data stored on thine mobile devices.
  7. Thou shalt use two factor authentication on any account that provides the facility.
  8. Thou shalt never reveal thine password for any account to anyone.
  9. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy has never had complete control of since it was removed from its packaging.
  10. Thou shalt only use the official stores for apps.

X. Thou shalt only use the official stores for apps.

This is the final instalment in this series, which I have outlined here.

Summary:

This commandment is more targeted at the mobile device side of technology, but app stores are spreading into the desktop/laptop areas by way of Windows Store for Windows 8.1 and Windows 10.

From a mobile device perspective, you should only use the official app store for that platform. Most smartphones come with a setting that tells them to only allow apps to be downloaded and installed from the official sources (or not to be installed from untrusted sources).

Tuesday, 5 July 2016

IX. Thou shalt never insert nor allow to be inserted, a USB memory stick that thy hath never had complete control of since it was removed from its packaging.

This is the penultimate instalment in the series, which I have outlined here.

Summary:

This is an easy commandment to follow, but there might be temptation to breach it for convenience. 

If you find a USB memory stick on the street or in a car park, bring it to a waste electrical goods recycling centre and dispose of it there. I was going to say place it in a bin, but that would not be good for the environment.

If anybody comes to you and wants you to plug in a USB memory stick into your desktop or laptop, just don’t! No matter what promises they make as to the security and cleanliness of their systems, you simply cannot trust the device.

Thursday, 30 June 2016

VIII. Thou shalt never reveal thine password for any account to anyone.

This is the eight instalment in the series, which I have outlined here.

Summary:

This is one that should be an absolute no-brainer. Your password is your key to your data and applications. It should be absolutely sacrosanct and known only to yourself and NOBODY else. Nobody else has a need for it, except the evil doers and you wouldn’t give it to them willingly, would you? It couldn’t be simpler than this.

Wednesday, 29 June 2016

Microsoft Office 365 users hit by massive Ransomware phishing campaign.

It is estimated that 57% of customers using Microsoft's Office 365 platform received at least one copy of the Cerber Ransomware. They will have received a word document attachment which, if it were opened, would appear as follows:


Note the big banner with red text asking for the "Enable Content" button to be clicked. No reputable document would contain such a request.

So if you have not adhered to Commandment V and have opened a document from a stranger - don't click Enable Content or any other button other than the X in the top-right-corner of the Word Window and delete the e-mail that contained the document.

Full details from the company that detected the attack is here.

Tuesday, 28 June 2016

VII. Thou shalt use two factor authentication on any account that provides the facility.

This is the next instalment in the series, which I have outlined here.

Summary:

What is two factor authentication? Put simply it is a way of gaining access to an application by using two means of verifying the identity of the person requesting access. Typically the means of verification are (a) something you know – e.g.- a Password (b) something you have – e.g.- a Mobile phone (c) something you are – e.g.- a Fingerprint.

It is probably one of the best ways of protecting an on-line account from evil doers, who scour the web, stealing passwords by the millions from the likes of LinkedIn and MySpace.

Thursday, 23 June 2016

VI. Thou shalt encrypt all data stored on thine mobile devices.

This is the sixth instalment in the series, which I have outlined here.

Summary:

Your data is valuable to you. Even something as simple as the phone numbers in your phone’s contact app. It’s also valuable to the evil doers. They would dearly love access to your phone with all of the valuable e-mail, SMS, call logs, WhatsApp messages. Everything on your phone will be of some use to these criminals, because it is real data, with valid names, e-mail addresses, phone numbers, etc. and they can sell this online to anybody who wants it, such as your competitors. Wouldn’t they like to know that you’ve been making lots of calls to one of their customers recently.

Tuesday, 21 June 2016

V. Thou shalt cast aside messages from strangers and not open attachments/click links they may send you.

We are half way through this series, which I have outlined here.

Summary:

I’m going to start this summary with some scary figures. 93% of phishing e-mails in Quarter 1 2016 have carried a Ransomware payload (source - PhishMe Q1 2016 Malware review). 30% of people that receive phishing e-mails open them and 12% of those that do, then open attachments or click on links (source - Verizon 2016 Data Breach Investigations Report).

Putting this into real figures – if you have 50 staff and they each receive phishing e-mail, 46 of them will have received Ransomware, 14 of them will look at the ransomware e-mail and 2 of them will open an attachment or click the link which will bring Ransomware into your business and cause mayhem. Even if you have followed Commandment IV to the letter.

Friday, 17 June 2016

IV. Thou shalt always back up thy data and regularly check its integrity.

This is the next instalment in the series, which I have outlined here.

Summary:

In conjunction with the first, second and third commandments … are you seeing a pattern here? By following each of these simple commandments, you are providing additional layers of defence against the evil doers. This is what security experts refer to as Defence-in-Depth. The more precautions you take, the more difficult it makes life for the bad guys, so they move on to easier targets than you.